ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 3 sources: “ZDI Discloses Three Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerabilities” — merged summary and timeline →

ZDI-26-697: Linux Kernel NTFS3 Out-Of-Bounds Read Information Disclosure Vulnerability

mediumVulnerabilityimportance 25
AI summary · glm-5.3

ZDI-26-697: Linux Kernel NTFS3 out-of-bounds read rated CVSS 7.3 lets local low-privileged attackers disclose sensitive information.

ZDI advisory ZDI-26-697 describes an out-of-bounds read in the Linux Kernel NTFS3 driver rated CVSS 7.3. An attacker must first be able to execute low-privileged code on the target system to exploit the flaw. Successful exploitation leads to sensitive information disclosure. No CVE identifier is listed in the advisory.

  • Out-of-bounds read in Linux Kernel NTFS3 driver
  • CVSS 7.3, local information disclosure
  • Requires prior low-privileged code execution
  • No CVE assigned in advisory text
Full article

This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3.

This source does not provide full text. Read it at zerodayinitiative.com.